NIS2 and management liability: obligations and implementation deadlines

Jacek Włodarczyk | Senior Manger | Crowe Poland
9/17/2026
Business meeting

Just a few years ago, cybersecurity was viewed by many organisations as an issue for the IT department. Today, it has become one of the key areas of compliance and risk management.

The NIS2 Directive and the amendment to the National Cybersecurity System Act, effective from 3 April 2026, extend responsibility for digital security beyond technical teams. Managers of essential and important entities are responsible for carrying out cybersecurity-related tasks, while boards, senior management and business process owners must actively participate in cybersecurity risk management.

This means that organisations covered by the new regulations can no longer postpone their preparation efforts. October 2026 is particularly important, as 3 October marks the deadline for registering essential and important entities in the S46 system. This is the first obligation that the regulator can relatively easily verify, and failure to comply may become the starting point for a broader review of an organisation’s compliance with NIS2 requirements.

Order your NIS2 Compliance Audit today

NIS2 is not just another IT regulation


One of the most common mistakes is treating NIS2 as a technology project. In reality, the directive requires much more than implementing new security tools or purchasing additional monitoring solutions.

The new regulations impose an obligation to systematically manage cybersecurity risks, implement appropriate organisational and technical measures, report incidents and ensure business continuity. Furthermore, organisations must be able to demonstrate that these activities are documented and can be verified by the supervisory authority.

From a compliance perspective, this means building a coherent information security management system that includes policies, procedures, risk assessments, supplier management, employee training and regular reviews of the effectiveness of implemented controls.

Who is affected by the new obligations?


The scope of entities covered by the regulations has been significantly expanded. In Poland, the number of organisations subject to the requirements has increased from several hundred entities to tens of thousands of organisations. As a result, NIS2 obligations apply not only to critical infrastructure operators, but also to many businesses operating in sectors such as transport, healthcare, energy, finance, manufacturing, public administration, digital services and waste management.

At the same time, many organisations have still not carried out a formal self-assessment to determine whether they qualify as an essential or important entity. This is particularly risky because the obligation to identify an organisation’s status rests with the organisation itself, not with the regulator.

What penalties apply for non-compliance with NIS2?


The issue of sanctions is one of the main reasons why NIS2 is increasingly appearing on the agendas of boards and audit committees.

Polish regulations provide for substantial financial penalties for organisations that fail to comply with obligations arising from the National Cybersecurity System Act. In the most serious cases, where violations create a direct and significant threat to national security or public safety, sanctions may reach as much as PLN 100 million.

Additionally, the regulations provide for sanctions aligned with the levels specified in NIS2:


  • for essential entities, up to EUR 10 million or 2% of global annual turnover;
  • for important entities, up to EUR 7 million or 1.4% of global annual turnover.

It is worth noting that the regulations are not focused solely on penalising organisations. There is also a growing emphasis on the accountability of individuals in management positions.

Management liability is becoming a real risk


One of the most significant changes introduced by NIS2 is the direct involvement of organisational leadership in cybersecurity management. Boards can no longer limit themselves to delegating responsibility to IT departments.

The new regulations require active oversight of security processes, approval of policies, monitoring of risk levels and the allocation of adequate resources to meet regulatory obligations. Cybersecurity is therefore becoming a corporate governance issue, alongside financial, tax and other compliance matters.

For many organisations, this means changing their management model and including cybersecurity in regular reports presented to the management board and supervisory board.

Why is October 2026 so important?


Although full implementation of all requirements has been phased over time, the deadline of 3 October 2026 represents the first significant test of organisational readiness. By that date, entities covered by the regulations should complete registration in the S46 system.

Many businesses mistakenly assume they still have plenty of time to implement a full compliance programme. In reality, effective preparation requires risk assessments, gap analyses, documentation development, procedure implementation, employee training and often the modernisation of the IT environment.

Achieving full compliance may take anywhere from several months to well over a year, particularly in larger and more complex organisations.

How can organisations prepare for NIS2 compliance and audits?


The most effective approach includes several stages:

  1. Verifying whether the organisation falls within the scope of NIS2.
  2. Conducting a readiness assessment and gap analysis.
  3. Developing an information security management system.
  4. Implementing cybersecurity risk management processes.
  5. Establishing governance for cooperation with suppliers and business partners.
  6. Preparing incident reporting procedures.
  7. Training employees and management teams.
  8. Preparing the organisation for future audits and inspections.

It is no coincidence that an increasing number of organisations begin their preparations with an NIS2 compliance audit. Such an audit helps determine the actual maturity level of cybersecurity and estimate the effort required to achieve compliance.

Summary


NIS2 is one of the most significant regulatory changes in recent years within the areas of cybersecurity and compliance.Organisations covered by the new regulations must prepare not only for new operational obligations, but also for increased management accountability and substantial financial penalties.

The first step should be to promptly confirm the organisation’s status, plan registration in the S46 system and conduct a readiness assessment to identify gaps and establish implementation priorities.

Frequently asked questions (FAQ)


Do all companies need to implement NIS2?

No. The obligations apply only to entities that meet specific sectoral and size-related criteria set out in the regulations. In many cases, an individual assessment of the organisation’s status is required.

 

What is the next key NIS2 deadline?

For entities meeting the criteria on the date the amendment entered into force, the deadline for applying for entry into the KSC Register is 3 October 2026, unless they were entered automatically. By 3 April 2027, entities should begin using the S46 system and implement obligations arising from the Act. The first mandatory audit for essential entities that were not previously operators of essential services must be completed by 3 April 2028.

What penalties apply for non-compliance?

Depending on the type of violation, penalties may reach EUR 7-10 million or, respectively, 1.4-2% of global annual turnover. In specific circumstances, Polish regulations also provide for penalties of up to PLN 100 million.

Is the management board liable for cybersecurity?

Yes. The National Cybersecurity System Act increases the responsibility of the manager of an essential or important entity for cybersecurity-related tasks, risk management and the implementation of appropriate protective measures. The possibility of imposing a personal penalty, as well as the amount and method of calculation, depend on the entity’s status, the type of violation and the specific legal conditions set out in the Act.

Penalties may include:

  • up to 100% of the annual remuneration of the entity’s manager;
  • in cases specified by law, a personal financial penalty may be imposed on the manager of an essential or important entity, with the amount determined according to statutory criteria and requiring verification against the relevant legal provision.
How long does NIS2 implementation take?

It depends on the organisation’s maturity level. In practice, the process may take anywhere from several months to more than a year, especially in large and geographically dispersed organisations.

Does NIS2 apply only to IT departments?

No. The regulations apply to the entire organisation, including the management board, compliance, HR, procurement, legal teams and all business process owners.

Need support with implementing NIS2 requirements in your organisation?

Jacek Włodarczyk
Jacek Włodarczyk
Senior ManagerCrowe

See also:



Consulting